CTD-000170

Missing Conditional Access Policies for blocking legacy authentication

High
Entra ID
Credential Access Defense Evasion Persistence
v6

Signature Identity

CTD-000170
Threat ID
6
Version
IOE
Indicator Type

Threat Description

The absence of Conditional Access Policies to block legacy authentication poses a significant security vulnerability. Legacy authentication protocols like POP, IMAP, and SMTP do not support modern authentication methods such as multifactor authentication (MFA). These protocols are frequently exploited by threat actors for credential stuffing, brute force, and phishing attacks. Enforcing a block on legacy authentication greatly diminishes the risk of unauthorized access and enhances the overall security posture.

MITRE ATT&CK: Attack Tactics

Credential Access Defense Evasion Persistence

D3FEND: Defend Tactics

D3-APA (Access Policy Administration)

Remediation

  1. Review sign-in logs in Entra ID to identify users and applications relying on legacy authentication.
  2. Navigate to Entra ID > Sign-ins and filter for Legacy Authentication Clients.
  3. To create Conditional Access Policy, go to Entra ID > Security > Conditional Access.
  4. Configure a new policy with the following Assignments:
    1. Users: All users or specific groups
    2. Applications: All cloud apps or specific critical apps
  5. Configure a new policy with the following Conditions:
    1. Client Apps: Select Other clients and check legacy authentication protocols (e.g., POP, IMAP, SMTP)
    2. Controls: Block access
  6. Navigate to Entra ID > Security > Authentication Methods > Modern Authentication.
  7. Turn off legacy authentication protocols where feasible.
  8. Notify affected users and provide guidance for transitioning to modern authentication.
  9. Continuously monitor authentication logs to ensure compliance.
  10. Deploy in a phased manner to minimize disruption to critical services.

Frequently Asked Questions

What does Missing Conditional Access Policies for blocking legacy authentication mean?

Missing Conditional Access Policies for blocking legacy authentication means that your Entra ID environment is not enforcing a block on legacy authentication protocols like POP, IMAP, and SMTP. This omission leaves the organization vulnerable to attacks that exploit these outdated methods.

This vulnerability allows attackers to bypass modern authentication requirements, enabling unauthorized access and security breaches. The absence of policies blocking legacy protocols directly increases the risk of successful attacks.

Attackers exploit this vulnerability by using legacy protocols like POP, IMAP, or SMTP to bypass modern authentication requirements. This allows them to perform credential stuffing and brute force attacks with greater ease.

Cayosoft Guardian detects Missing Conditional Access Policies for blocking legacy authentication by continuously monitoring your Entra ID environment for the absence of policies that block legacy authentication protocols. When such a policy is missing, Guardian flags it as a security issue.

Cayosoft Guardian helps reduce the risk by alerting administrators to create and enforce policies that block legacy authentication protocols, ensuring the organization is protected against attacks that exploit these outdated methods.

Stop AD Threats As They Happen

Cayosoft Protector provides continuous monitoring and real-time alerts across your entire Microsoft Identity stack

Classification
Systems
Entra ID
Themes
Account protection Tenant-wide
Attack Tactics
Credential Access Defense Evasion Persistence
Defend Tactics
D3-APA (Access Policy Administration)
Indicator Types
IOE
Related Threats
CTD-000139
Kerberos Constrained Delegation: krbtgt Risks
Critical
CTD-000122
Active Directory Schema Update Permission Risks
Critical